Skip to main content
VerifiedExfiltration

SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out

Varonis disclosed in June 2026 that a query parameter in a crafted link was interpreted by Microsoft 365 Copilot Search as instructions. Chained with a rendering race condition and a server side request forgery, one click made the copilot search the victim's mailbox and send the results out through an image request, using the victim's full directory permissions.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0020
Kind
Exfiltration
Jurisdiction
United States
Last verified
Added
  • The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
  • The chain combined parameter to prompt injection, an HTML rendering race condition and a server side request forgery in a first party service.
  • The enterprise copilot runs with the user's full directory permissions, so the attacker inherited reach into mail, calendar, document libraries and file storage.
  • The research notes the user sees only a response that may look odd, by which time the data has already gone.
  • Microsoft assigned CVE-2026-42824 and patched it with no user action required.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
A URL query parameter carried instruction level authority inside the agent.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
AuthorizationSilent
The copilot's full directory permissions were inherited by whoever controlled the link.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
LimitsSilent
The content security policy was bypassed through a first party request forgery, so the egress boundary failed on a trusted domain.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
Human approvalSilent
One click was the whole interaction; nothing confirmed the search or the outbound request.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
Logging and auditSilent
The user's only signal was an odd looking answer, which is not a detection control.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
RevocationStated
The vendor patched the chain on its own service with no user action required.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
AccountabilityStated
A CVE was assigned and named researchers published the chain with a timeline.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.

What it changes

For a team deploying an agent

An allowlist of trusted domains is not an egress control when a trusted domain will fetch a URL for you. Ask your vendor which outbound channels an agent can reach and what closes them deterministically rather than by classifier. On your side, reduce what the copilot can see: scope its directory permissions to the libraries a role needs, so one click reaches less.

Sources

What this record was verified against

  1. Varonis Threat Labs, SearchLeakPrimary · 15 June 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0020 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), searchleak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out.
APA
GAGE (Global Academy of Generative-AI Education). (2026). SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft
MLA
"SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft.
Chicago
GAGE (Global Academy of Generative-AI Education). "SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.